diff --git a/advisories/unreviewed/2024/07/GHSA-79hg-h6r6-64mm/GHSA-79hg-h6r6-64mm.json b/advisories/unreviewed/2024/07/GHSA-79hg-h6r6-64mm/GHSA-79hg-h6r6-64mm.json index 40c9c885a76..3feaba99b6b 100644 --- a/advisories/unreviewed/2024/07/GHSA-79hg-h6r6-64mm/GHSA-79hg-h6r6-64mm.json +++ b/advisories/unreviewed/2024/07/GHSA-79hg-h6r6-64mm/GHSA-79hg-h6r6-64mm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-79hg-h6r6-64mm", - "modified": "2024-08-02T18:31:10Z", + "modified": "2024-08-07T06:31:09Z", "published": "2024-07-08T18:31:18Z", "aliases": [ "CVE-2024-6409" @@ -27,51 +27,7 @@ }, { "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:4457" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:4613" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:4716" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2024:4910" - }, - { - "type": "WEB", - "url": "https://access.redhat.com/security/cve/CVE-2024-6409" - }, - { - "type": "WEB", - "url": "https://almalinux.org/blog/2024-07-09-cve-2024-6409" - }, - { - "type": "WEB", - "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2295085" - }, - { - "type": "WEB", - "url": "https://bugzilla.suse.com/show_bug.cgi?id=1227217" - }, - { - "type": "WEB", - "url": "https://explore.alas.aws.amazon.com/CVE-2024-6409.html" - }, - { - "type": "WEB", - "url": "https://security-tracker.debian.org/tracker/CVE-2024-6409" - }, - { - "type": "WEB", - "url": "https://security.netapp.com/advisory/ntap-20240712-0003" - }, - { - "type": "WEB", - "url": "https://sig-security.rocky.page/issues/CVE-2024-6409" + "url": "https://www.suse.com/security/cve/CVE-2024-6409.html" }, { "type": "WEB", @@ -79,7 +35,55 @@ }, { "type": "WEB", - "url": "https://www.suse.com/security/cve/CVE-2024-6409.html" + "url": "https://sig-security.rocky.page/issues/CVE-2024-6409" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240712-0003" + }, + { + "type": "WEB", + "url": "https://security-tracker.debian.org/tracker/CVE-2024-6409" + }, + { + "type": "WEB", + "url": "https://explore.alas.aws.amazon.com/CVE-2024-6409.html" + }, + { + "type": "WEB", + "url": "https://bugzilla.suse.com/show_bug.cgi?id=1227217" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2295085" + }, + { + "type": "WEB", + "url": "https://almalinux.org/blog/2024-07-09-cve-2024-6409" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-6409" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4955" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4910" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4716" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4613" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:4457" }, { "type": "WEB", diff --git a/advisories/unreviewed/2024/08/GHSA-4jhq-mm86-8cmq/GHSA-4jhq-mm86-8cmq.json b/advisories/unreviewed/2024/08/GHSA-4jhq-mm86-8cmq/GHSA-4jhq-mm86-8cmq.json new file mode 100644 index 00000000000..9acd4ccb5b3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-4jhq-mm86-8cmq/GHSA-4jhq-mm86-8cmq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jhq-mm86-8cmq", + "modified": "2024-08-07T06:31:09Z", + "published": "2024-08-07T06:31:09Z", + "aliases": [ + "CVE-2024-36131" + ], + "details": "An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the appliance.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36131" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-for-Mobile-EPMM-July-2024" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T04:17:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-54cg-4vp2-8f67/GHSA-54cg-4vp2-8f67.json b/advisories/unreviewed/2024/08/GHSA-54cg-4vp2-8f67/GHSA-54cg-4vp2-8f67.json new file mode 100644 index 00000000000..22f588a763c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-54cg-4vp2-8f67/GHSA-54cg-4vp2-8f67.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54cg-4vp2-8f67", + "modified": "2024-08-07T06:31:09Z", + "published": "2024-08-07T06:31:09Z", + "aliases": [ + "CVE-2024-36132" + ], + "details": "Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive resources.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36132" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-for-Mobile-EPMM-July-2024" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T04:17:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-5rx8-chp2-fvxf/GHSA-5rx8-chp2-fvxf.json b/advisories/unreviewed/2024/08/GHSA-5rx8-chp2-fvxf/GHSA-5rx8-chp2-fvxf.json new file mode 100644 index 00000000000..cdc595ff4ce --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-5rx8-chp2-fvxf/GHSA-5rx8-chp2-fvxf.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rx8-chp2-fvxf", + "modified": "2024-08-07T06:31:10Z", + "published": "2024-08-07T06:31:10Z", + "aliases": [ + "CVE-2024-37403" + ], + "details": "Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, resulting in a path traversal-affiliated vulnerability. This potentially enables other malicious apps on the device to read sensitive information stored in the app root.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37403" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-CVE-2024-37403-Dirty-Stream-for-Ivanti-Docs-Work-for-Android" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T04:17:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cmm9-h7p3-233m/GHSA-cmm9-h7p3-233m.json b/advisories/unreviewed/2024/08/GHSA-cmm9-h7p3-233m/GHSA-cmm9-h7p3-233m.json new file mode 100644 index 00000000000..648496fcef5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-cmm9-h7p3-233m/GHSA-cmm9-h7p3-233m.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmm9-h7p3-233m", + "modified": "2024-08-07T06:31:09Z", + "published": "2024-08-07T06:31:09Z", + "aliases": [ + "CVE-2024-34788" + ], + "details": "An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive information", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34788" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-for-Mobile-EPMM-July-2024" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T04:17:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-fjrj-vrrh-qjx6/GHSA-fjrj-vrrh-qjx6.json b/advisories/unreviewed/2024/08/GHSA-fjrj-vrrh-qjx6/GHSA-fjrj-vrrh-qjx6.json new file mode 100644 index 00000000000..3d23cc69550 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-fjrj-vrrh-qjx6/GHSA-fjrj-vrrh-qjx6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjrj-vrrh-qjx6", + "modified": "2024-08-07T06:31:10Z", + "published": "2024-08-07T06:31:10Z", + "aliases": [ + "CVE-2024-6494" + ], + "details": "The WordPress File Upload WordPress plugin before 4.24.8 does not properly sanitize and escape certain parameters, which could allow unauthenticated users to execute stored cross-site scripting (XSS) attacks.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6494" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/5b21a9be-b5fe-47ef-91c7-018dd42f763f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T06:16:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-j3pw-x73p-86xf/GHSA-j3pw-x73p-86xf.json b/advisories/unreviewed/2024/08/GHSA-j3pw-x73p-86xf/GHSA-j3pw-x73p-86xf.json new file mode 100644 index 00000000000..3b18bc87982 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-j3pw-x73p-86xf/GHSA-j3pw-x73p-86xf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3pw-x73p-86xf", + "modified": "2024-08-07T06:31:10Z", + "published": "2024-08-07T06:31:10Z", + "aliases": [ + "CVE-2024-3973" + ], + "details": "The House Manager WordPress plugin through 1.0.8.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3973" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/8c6ce66e-091a-41da-a13d-5f80cadb499a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T06:16:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-ww6r-jv53-52xq/GHSA-ww6r-jv53-52xq.json b/advisories/unreviewed/2024/08/GHSA-ww6r-jv53-52xq/GHSA-ww6r-jv53-52xq.json new file mode 100644 index 00000000000..e4a5e3407ef --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-ww6r-jv53-52xq/GHSA-ww6r-jv53-52xq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ww6r-jv53-52xq", + "modified": "2024-08-07T06:31:09Z", + "published": "2024-08-07T06:31:09Z", + "aliases": [ + "CVE-2024-36130" + ], + "details": "An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36130" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-for-Mobile-EPMM-July-2024" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-07T04:17:17Z" + } +} \ No newline at end of file